apache-airflow-providers-keycloak is vulnerable to Reliance on Cookies without Validation and Integrity Checking
91
Critical Risk
From Airflow 3.3, the Keycloak auth manager derives a user's identity from a cookie value without checking that Keycloak signed the cookie. A caller who can set that cookie can present an arbitrary Keycloak identity, and Airflow grants access under it. The fix validates the cookie's signature before trusting the identity it carries.
You are affected if you are using a version that falls within the vulnerable range and you use the Keycloak auth manager with cookies reaching Airflow from an untrusted browser context.
apache-airflow-providers-keycloak is vulnerable to Reliance on Cookies without Validation and Integrity Checking in versions 0.0.1 - 0.9.0.
Upgrade the apache-airflow-providers-keycloak library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.